2 months ago
Remote, United Kingdom +2 moreStaff+
Responsibilities
- Lead the secure design of new cloud services and solutions in line with security strategies.
- Identify security issues in existing system designs and recommend mitigations balancing cost, risk, and usability.
- Apply security practices across application, infrastructure, network, web application, cryptographic, and software-development lifecycles.
- Work with delivery teams to promote secure practices throughout the software development journey.
- Test the security of software and infrastructure using appropriate security tools.
- Educate customers, colleagues, and wider communities on effective security practices.
- Manage, coach, and develop a small number of staff, including employee performance and career development.
- Provide direction and leadership while solving challenging security problems.
- Communicate security complexities to senior stakeholders and development teams.
Requirements
- Expertise leading secure design for new cloud services and solutions.
- Expertise identifying security issues in existing system designs and defining sensible mitigations.
- Knowledge of security standards and regulations including NCSC, ISO, SoC, NIST, PCI, and GDPR.
- Experience in AI, ML, data, cloud, M365, or security architecture.
- Experience in application architecture, software development, or infrastructure architecture.
- Industry experience in public, healthcare, defence, or commercial sectors.
- Experience testing software and infrastructure security with appropriate tools.
- Experience with continuous security, continuous integration, and continuous delivery techniques.
- Experience with network security, including OSI and TCP/IP; web application security, including OWASP; and cryptographic controls, including PKI and TLS.
- Demonstrated ability to manage, mentor, and coach team members and the wider community.
- Excellent communication skills for audiences with varied technical abilities.
- Desirable experience with identity management and authentication or authorization products and patterns.
- Desirable involvement across the full security lifecycle and end-to-end security, including governance, risk and compliance, operational security, supply chain security, and secure user management.
- Active participation in knowledge-sharing activities.
- Penetration specialist certifications are desirable.
